Skip to content
Search

Latest Stories

Google researcher links ransomware attack to North Korea

An security researcher with Google has found evidence suggesting that North Korean hackers may have carried out the "unprecedented" ransomware cyberattack that hit over 150 countries, including India.

Neel Mehta has published a code which a Russian security firm has termed as the "most significant clue to date", the BBC reported today.


The code, published on Twitter, is exclusive to North Korean hackers, researchers said.

Researchers have said that some of the code used in Friday's ransomware, known as WannaCry software, was nearly identical to the code used by the Lazarus Group, a group of North Korean hackers who used a similar version for the devastating hack of Sony Pictures Entertainment in 2014 and the last years hack of Bangladesh Central Bank.

Security experts are now cautiously linking the Lazarus Group to this latest attack after the discovery by Mehta.

Mehta has found similarities between code found within WannaCry and other tools believed to have been created by the Lazarus Group in the past, BBC reported.

Security expert Prof Alan Woodward said that time stamps within the original WannaCry code are set to UTC +9 - China's time zone - and the text demanding the ransom uses what reads like machine-translated English, but a Chinese segment apparently written by a native speaker, the report said.

"As you can see it is pretty thin and all circumstantial. However, it is worth further investigation," Woodward said.

"Neel Mehta's discovery is the most significant clue to date regarding the origins of WannaCry," said Russian security firm Kaspersky, but noted a lot more information is needed about earlier versions of WannaCry before any firm conclusion can be reached, it reported.

"We believe it is important that other researchers around the world investigate these similarities and attempt to discover more facts about the origin of WannaCry," it said.

Attributing cyberattacks can be notoriously difficult - often relying on consensus rather than confirmation, the report said.

North Korea has never admitted any involvement in the Sony Pictures hack - and while security researchers, and the US government, have confidence in the theory, neither can rule out the possibility of a false flag, it said.

Skilled hackers may have simply made it look like it had origins in North Korea by using similar techniques.

In the case of WannaCry, it is possible that hackers simply copied code from earlier attacks by the Lazarus Group.

"There's a lot of ifs in there. It wouldn't stand up in court as it is. But its worth looking deeper, being conscious of confirmation bias now that North Korea has been identified as a possibility," Woodward said.

Its the strongest theory yet as to the origin of WannaCry, but there are also details that arguably point away from it being the work of North Korea.

First, China was among the countries worst hit, and not accidentally - the hackers made sure there was a version of the ransom note written in Chinese. It seems unlikely North Korea would want to antagonise its strongest ally. Russia too was badly affected, the report said.

Second, North Korean cyber-attacks have typically been far more targeted, often with a political goal in mind.

In the case of Sony Pictures, hackers sought to prevent the release of The Interview, a film that mocked North Korean leader Kim Jong-Un. WannaCry, in contrast, was wildly indiscriminate - it would infect anything and everything it could, the report said.

Finally, if the plan was simply to make money, its been pretty unsuccessful on that front too - only around $60,000 has been paid in ransoms, according to analysis of Bitcoin accounts being used by the criminals.

With more than 200,000 machines infected, its a terrible return, the report said.

On Friday, Europol Director Rob Wainwright said: "The global reach is unprecedented. The latest count is over 200,000 victims in at least 150 countries and those victims many of those will be businesses including large corporations".

The most disruptive attacks were reported in the UK, where hospitals and clinics were forced to turn away patients after losing access to computers.

More For You

Trump

Trump said the suspect had been arrested earlier for 'terrible crimes,' including child sex abuse, grand theft auto and false imprisonment, but was released under the Biden administration because Cuba refused to take him back.

Getty Images

Trump says accused in Dallas motel beheading will face first-degree murder charge

US PRESIDENT Donald Trump has described Chandra Mouli “Bob” Nagamallaiah, the Indian-origin motel manager killed in Dallas, as a “well-respected person” and said the accused will face a first-degree murder charge.

Nagamallaiah, 50, was killed last week at the Downtown Suites motel by co-worker Yordanis Cobos-Martinez, a 37-year-old undocumented Cuban immigrant with a criminal history.

Keep ReadingShow less
Starmer Mandelson

Starmer talks with Mandelson during a welcome reception at the ambassador's residence on February 26, 2025 in Washington, DC.

Getty

Starmer under pressure from party MPs after Mandelson dismissal

PRIME MINISTER Keir Starmer is facing questions within the Labour party after the sacking of US ambassador Peter Mandelson.

Mandelson was removed last week after Bloomberg published emails showing messages of support he sent following Jeffrey Epstein’s conviction for sex offences. The dismissal comes just ahead of US president Donald Trump’s state visit.

Keep ReadingShow less
Nepal’s new leader pledges to act on Gen Z calls to end corruption

Officials greet newly-elected Prime Minister of Nepal's interim government Sushila Karki (R) as she arrives at the prime minister's office in Kathmandu on September 14, 2025. (Photo by PRABIN RANABHAT/AFP via Getty Images)

Nepal’s new leader pledges to act on Gen Z calls to end corruption

NEPAL’s new interim prime minister Sushila Karki on Sunday (14) pledged to act on protesters’ calls to end corruption and restore trust in government, as the country struggles with the aftermath of its worst political unrest in decades.

“We have to work according to the thinking of the Gen Z generation,” Karki said in her first address to the nation since taking office on Friday (12). “What this group is demanding is the end of corruption, good governance and economic equality. We will not stay here more than six months in any situation. We will complete our responsibilities and hand over to the next parliament and ministers.”

Keep ReadingShow less
UK secures £1.25bn US investment ahead of Trump’s visit

US president Donald Trump and UK prime minister Sir Keir Starmer arrive at Trump International Golf Links on July 28, 2025 in Balmedie, Scotland. (Photo by Jane Barlow-WPA Pool/Getty Images)

UK secures £1.25bn US investment ahead of Trump’s visit

THE British government has announced over £1.25 billion ($1.69bn) in fresh investment from major US financial firms, including PayPal, Bank of America, Citigroup and S&P Global, ahead of a state visit by president Donald Trump.

The investment is expected to create 1,800 jobs across London, Edinburgh, Belfast and Manchester, and deepen transatlantic financial ties, the Department for Business and Trade said.

Keep ReadingShow less
Nearly 150,000 join anti-migrant protest in London as clashes erupt

Protesters wave Union Jack and St George's England flags during the "Unite The Kingdom" rally on Westminster Bridge by the Houses of Parliament on September 13, 2025 in London, England. (Photo by Christopher Furlong/Getty Images)

Nearly 150,000 join anti-migrant protest in London as clashes erupt

MORE THAN 100,000 protesters marched through central London on Saturday (13), carrying flags of England and Britain and scuffling with police in one of the UK's biggest right-wing demonstrations of modern times.

London's Metropolitan Police said the "Unite the Kingdom" march, organised by anti-immigrant activist Tommy Robinson, was attended by nearly 150,000 people, who were kept apart from a "Stand Up to Racism" counter-protest attended by around 5,000.

Keep ReadingShow less